HIPAA & Business Associate Agreements (BAA)
What HIPAA means for your front desk, whether an AI receptionist can be compliant, and how to get a signed BAA from Ansora
Last updated July 5, 2026 · Ansora, Miami, FL
The short version
If you run a dental practice, medical office, or med-spa, your front desk hears protected health information (PHI) every day — who's calling, what they're calling about, and when they booked. HIPAA follows that information to any vendor who handles it on your behalf, including an AI receptionist. Here's the honest version: Ansora is not a covered entity and does not practice medicine. When we answer calls for a healthcare client, we act as your Business Associate, and we'll sign a Business Associate Agreement (BAA) that puts that in writing. "HIPAA-compliant" is not a badge a vendor can wear on its own — compliance is a shared responsibility between you and every vendor in the chain, and it depends on a signed BAA, real safeguards (encryption, access controls, PHI-minimization, short- or zero-retention call recording), and how you actually run the practice. Below we walk through what HIPAA means for your phones, whether an AI receptionist can be compliant (nuanced answer: it can be, under the right setup), what a BAA does, exactly how Ansora handles PHI, your recording and retention options for healthcare, what stays your responsibility, and how to get a BAA in place before you go live. This is written in plain English. It is not legal advice, and you should have your own attorney or HIPAA compliance advisor review it before you rely on it.
01What HIPAA means for your front desk
HIPAA — the Health Insurance Portability and Accountability Act — governs how protected health information (PHI) is handled by covered entities (like your practice) and the vendors that work with them. PHI is not just chart notes and diagnoses. In a front-desk context, it's the everyday stuff: a caller's name tied to the fact that they're your patient, the phone number they're calling from, the reason for the visit ("I need to get this filling looked at," "I'm calling about my Botox appointment"), appointment dates, and anything about their treatment that comes up on the call.
The moment your phone rings, PHI is in play. A missed call, a voicemail, a booking, a text confirmation — each one can carry PHI. That's true whether a human receptionist, a call center, or an AI answers. HIPAA doesn't care who or what picks up; it cares about how the information is protected once it's created.
This matters for your phones specifically because the front desk is where PHI is most casually created and most easily mishandled — sticky notes, shared voicemail boxes, unencrypted texts, call recordings nobody thought about. When you bring in any tool that answers, records, transcribes, or texts on your behalf, that tool becomes part of your HIPAA footprint. Choosing that tool carefully, and getting the paperwork right, is part of running a compliant front desk.
- PHI at the front desk = a caller's identity as your patient, their number, the reason for the call, appointment details, and anything about their care.
- Any tool that answers, records, transcribes, or texts on your behalf becomes part of your HIPAA footprint.
- HIPAA applies regardless of whether a human, a call center, or an AI handles the call.
02Is an AI receptionist HIPAA-compliant? (The honest answer)
Here's where a lot of vendors oversell, so we'll be precise. "HIPAA-compliant" is not a certification you earn once and stamp on a website. There is no government body that hands out a "HIPAA-compliant" seal for software. Compliance is a state you and your vendors maintain together — it depends on a signed BAA, appropriate safeguards, and how the system is actually configured and used.
So the honest answer is: an AI receptionist can be part of a HIPAA-compliant setup, when three things are true. First, the vendor is willing to act as your Business Associate and sign a BAA. Second, the underlying technology has appropriate safeguards — encryption, access controls, and the ability to limit or avoid storing PHI. Third, you configure and operate it in line with your own policies. Miss any one of those and "HIPAA-compliant" is just marketing.
Ansora will not tell you our AI receptionist is "HIPAA-certified," because no honest vendor can. What we will tell you is this: we act as a Business Associate for healthcare clients, we sign a BAA, and we offer the safeguards and PHI-minimization options that let you deploy it as part of a compliant front desk. The rest — your policies, your training, your notice of privacy practices — stays with you. That shared model is the whole point of the next few sections.
One more honest note: not every AI-receptionist vendor will sign a BAA, and some consumer-grade voice tools explicitly refuse to handle PHI. If a vendor won't sign a BAA, that's your answer — they cannot be used for healthcare calls that involve PHI, full stop. Ansora will sign one.
- There is no official "HIPAA-certified" stamp for software — any vendor claiming one is overselling.
- An AI receptionist CAN be part of a compliant setup when: (1) the vendor signs a BAA, (2) the tech has real safeguards, and (3) you operate it per your policies.
- Ansora signs a BAA and provides the safeguards; it does not claim to be "HIPAA-certified."
- A vendor that refuses to sign a BAA cannot lawfully handle your PHI — that's a clear disqualifier.
03Who Ansora is under HIPAA (Business Associate, not covered entity)
Your practice is the covered entity. You're the one with the direct relationship to the patient, the treatment, and the obligations under HIPAA. Ansora is not a covered entity — we don't provide healthcare, bill insurance, or practice medicine or dentistry. We don't diagnose, advise on treatment, or make clinical decisions, and the AI receptionist is not designed or permitted to give medical advice.
When we answer calls that involve PHI on your behalf, HIPAA calls us a Business Associate: a vendor that creates, receives, maintains, or transmits PHI to perform a service for a covered entity. That's the correct and honest classification. It means we take on specific obligations under HIPAA and under the BAA we sign with you — and it means you can hold us to them contractually.
Being a Business Associate also means we sit inside a chain. The subprocessors that make the receptionist work — the telephony provider, the voice and transcription layers, the LLM provider — are, in turn, our subprocessors (sometimes called "subcontractors" in HIPAA language). Where those providers handle PHI, we work to have appropriate agreements in place with them so the protection flows down the chain. We're honest that we cannot unilaterally guarantee a third party's internal practices; what we commit to is using each provider's available protections and agreements.
- You = covered entity. Ansora = Business Associate. Ansora is not a covered entity and does not practice medicine or give medical advice.
- As a Business Associate, Ansora takes on HIPAA obligations you can enforce through the BAA.
- Ansora's own vendors (telephony, voice, transcription, LLM) are subcontractors; where they handle PHI, Ansora works to flow BAA-style protections down the chain.
04The BAA: what it is and what it does
A Business Associate Agreement (BAA) is the contract HIPAA requires between a covered entity and a Business Associate before the Business Associate handles PHI. It's not optional paperwork — under HIPAA, you generally cannot lawfully hand PHI to a vendor for these purposes without one. The BAA is the document that makes an AI receptionist usable for a healthcare front desk.
In plain terms, the BAA puts Ansora's HIPAA obligations in writing. It defines the permitted uses of PHI (only to run the receptionist service you hired us for — never to sell, never for our own marketing, never to train some other company's product), requires appropriate safeguards, obligates us to report breaches involving PHI, addresses our subcontractors, and covers return or destruction of PHI when the relationship ends.
The BAA works alongside — not instead of — Ansora's other agreements. Our Data Processing Addendum (DPA) covers caller data generally under privacy law; the BAA specifically governs PHI for healthcare clients. Where the BAA and the DPA or Terms conflict on the handling of PHI, the BAA controls for PHI. So a healthcare client ends up with the BAA sitting on top of the standard agreements, tightening the rules for anything that qualifies as PHI.
- A BAA is legally required before a Business Associate handles PHI — you generally cannot skip it.
- It defines permitted PHI uses (only to run your service), requires safeguards, mandates breach reporting, and covers PHI return/destruction at the end.
- The BAA layers on top of Ansora's DPA and Terms, and controls over them for anything that is PHI.
05How Ansora handles PHI
Under a BAA, PHI gets handled to the minimum necessary standard and protected with concrete safeguards. Here's what that looks like in practice, honestly stated — including where we're still maturing.
Encryption. PHI is encrypted in transit (HTTPS/TLS) between the systems that carry your calls, and encrypted at rest in the databases that store transcripts, summaries, and appointment details. Where sensitive fields are captured, they receive additional protection.
Access controls. Access to PHI — and to call recordings in particular — is limited on a least-privilege basis to the staff who genuinely need it to build, operate, and support your receptionist. Personnel with access are under binding confidentiality obligations.
PHI-minimization and redaction options. The most reliable way to protect PHI is to not store more of it than the job requires. For healthcare clients we offer configuration that minimizes what's retained — for example, redacting sensitive details from transcripts and summaries, capturing only the fields needed to book and follow up, and steering the AI to avoid soliciting clinical detail it doesn't need. The receptionist's job is to route, book, and follow up — not to take a medical history.
No secondary use. PHI is used only to run the service you hired us for. We do not sell or share it, we do not use it for our own marketing, and we work to configure our AI subprocessors so your content is not used to train their models. We are honest that we cannot give an absolute standalone guarantee about a third party's internal practices — this is a commitment to use each provider's available no-training and business-tier protections.
Certifications, stated honestly. Ansora is not currently SOC 2 certified — SOC 2 is on our roadmap — and we do not claim a certification we don't hold. Signing a BAA is a contractual commitment to HIPAA obligations; it is not the same as an independent audit, and we won't pretend otherwise.
- Encryption of PHI in transit (TLS) and at rest; extra protection for sensitive fields.
- Least-privilege access; recording access limited to staff who need it; personnel under confidentiality obligations.
- PHI-minimization: redaction options, capturing only booking/follow-up fields, and an AI that doesn't solicit unnecessary clinical detail.
- PHI used only to run your service — never sold, never used for Ansora's marketing, and configured against model training where the provider allows.
- Honest on certs: not SOC 2 certified (on the roadmap); a signed BAA is a contractual commitment, not an independent audit.
06Call recording & retention options for healthcare
Call recordings are often the single biggest PHI liability at a front desk, because a recording captures everything a caller says. For healthcare clients we give you real control over whether calls are recorded and how long anything is kept.
Recording is your choice. You can run your receptionist with call recording off entirely, so no call audio is retained — the system still books appointments and follows up, it just doesn't keep a recording. If you do record, the required disclosure is handled at the start of the call, and consent handling is configured for your state (Florida, where Ansora is based, is a two-party-consent state, so disclosure is default-on there).
Short- or zero-retention for PHI. For healthcare verticals we offer a short-retention or zero-retention option: recordings and transcripts can be set to delete quickly, or not be retained at all, so PHI doesn't sit around longer than the workflow needs. This is different from our general default (call recordings default to roughly 90 days for non-healthcare clients) — for a healthcare BAA you can tighten that down significantly.
You set the policy. Retention is a setting you control, aligned to your own HIPAA retention policy and your notice of privacy practices. When the relationship ends, PHI is returned or destroyed per the BAA. The goal is simple: keep only what your front desk actually needs to run, for only as long as it needs it.
- You can run the receptionist with recording OFF — no call audio retained — and still book and follow up.
- If you record, disclosure and consent are handled at the start of the call, configured for your state (Florida is two-party-consent, default-on).
- Healthcare gets a short-/zero-retention option so recordings and transcripts don't linger (vs. the ~90-day default for non-healthcare).
- Retention is a setting you control to match your own policy; PHI is returned or destroyed when the relationship ends.
08What you're responsible for
Because so much of the compliance picture is on your side of the line, it's worth spelling out plainly. These are the things Ansora cannot do for you — they belong to you as the covered entity, and getting them right is what makes the deployment compliant end to end.
You maintain your own HIPAA program: policies, workforce training, your Notice of Privacy Practices, and your risk analysis. You decide what your front-desk workflow is allowed to collect and confirm your legal basis and any required consents — including call-recording consent and, for outbound texts or callbacks, appropriate consent under applicable law. You choose your recording and retention settings to match your retention policy. And you keep your own downstream systems compliant — the PMS/EHR you book into, the calendar you sync, the inbox where summaries land.
A special note on emergencies and clinical questions: an AI receptionist is a scheduling and intake tool, not a clinician and not a triage line. It should not be the front line for medical emergencies. Your setup should route urgent or clinical matters to a human per your practice's protocols, and your callers should be directed to appropriate care or emergency services when needed. We configure the receptionist to hand off rather than to advise — but making sure your emergency and clinical-escalation protocols are right is your responsibility.
- Maintain your HIPAA program: policies, training, Notice of Privacy Practices, and risk analysis.
- Decide what your workflow collects and secure required consents (recording consent; consent for outbound texts/callbacks).
- Choose recording and retention settings that match your own policy.
- Keep your downstream systems (PMS/EHR, calendar, email) compliant.
- Ensure emergencies and clinical questions route to a human — the AI is intake/scheduling, not a triage line or clinician.
09What Ansora does not do
In the spirit of being honest rather than salesy, here's what we explicitly don't do — so there's no confusion about the boundaries of the service.
We don't practice medicine or dentistry, we don't diagnose, and the receptionist doesn't give medical advice or clinical triage. We don't sell, rent, or trade PHI, and we don't use your patients' information to advertise to them or to build a product for someone else. We don't claim a "HIPAA certification" we don't have, and we don't claim SOC 2 certification (it's on our roadmap). We don't promise that simply using our tool makes you compliant — compliance is the shared model described above.
And we don't hold your data hostage. When you leave, PHI is returned or destroyed per the BAA, and you can take your patient records and your number with you.
- No practicing medicine/dentistry, no diagnosis, no clinical advice or triage from the AI.
- No selling, renting, or trading PHI; no using patient data for advertising or to train someone else's product.
- No fake certifications — no "HIPAA-certified" claim, and not SOC 2 certified (on the roadmap).
- No claim that the tool alone makes you compliant; no holding your data hostage on the way out.
10How to get a BAA in place
Getting a BAA signed with Ansora is a normal part of onboarding a healthcare client, and it happens before you go live with PHI. Here's the path.
Tell us you're a healthcare client. When you reach out — dental, medical, med-spa, or similar — let us know you handle PHI so we scope the setup for healthcare from the start: BAA, PHI-minimization defaults, and your recording/retention preferences. Email hello@ansora.net or mention it during your demo.
Sign the BAA before go-live. We'll provide our BAA for your (and your attorney's) review, and we sign it before the receptionist starts handling live calls that involve PHI. If your practice has its own BAA form you're required to use, tell us — we'll work with you on the specifics.
Configure the healthcare-appropriate settings. Together we set your recording choice (including off), your short-/zero-retention option, and the PHI-minimization/redaction configuration, then tune it on real calls in week one — the same fast, done-for-you setup Ansora is known for, just scoped for PHI.
One caveat, stated up front: a BAA is a contract, and the right form and terms for your practice depend on your situation. Have your own attorney or HIPAA compliance advisor review our BAA before you sign. We'd rather you go in with clear eyes than take our word for it.
- Tell us you're a healthcare client (email hello@ansora.net or mention it at your demo) so we scope for PHI from day one.
- We provide and sign a BAA before the receptionist handles live PHI; if you must use your own BAA form, we'll work with you.
- We configure recording (including off), short-/zero-retention, and PHI-minimization, then tune on real calls in week one.
- Have your attorney or HIPAA advisor review the BAA before signing.
11This is not legal advice — get it reviewed
This page is written in plain English to help you make an informed decision about whether an AI receptionist can fit into your HIPAA-compliant front desk. It is educational, not legal advice, and it does not create an attorney-client relationship or a BAA on its own — the BAA is a separate signed document.
HIPAA is fact-specific, and your obligations depend on your practice, your state, and how you operate. Before you rely on anything here — and before you sign a BAA — have a licensed attorney or a qualified HIPAA compliance advisor review it against your specific situation. The safeguards, retention options, and roles described here reflect how Ansora operates today and may be updated over time; the BAA you sign is the controlling document for PHI.
If you're ready to talk specifics, or you want our BAA to hand to your attorney, email hello@ansora.net. We'll be straight with you about what we can and can't do.
- Educational, not legal advice; this page does not itself create a BAA or an attorney-client relationship.
- HIPAA is fact-specific — have your attorney or HIPAA advisor review your setup and our BAA before relying on either.
- The signed BAA is the controlling document for PHI; contact hello@ansora.net to request it.
This document is written in plain English and isn't legal advice. Have it reviewed by an attorney before relying on it. Questions? Email hello@ansora.net.